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-^-, A multiparty quantum secret sharing (QSS) protocol is proposed by using swapping quantum 

(^ , entanglement of Bell states. The secret messages are imposed on Bell states by local unitary 



o 






operations. The secret messages are split into several parts and each part is distributed to a 



rj [ party so that no action of a subset of all the parties but their entire cooperation is able to 



read out the secret messages. In addition, the dense coding is used in this protocol to achieve 
a high efficiency. The security of the present multiparty QSS against eavesdropping has been 



r\i _ analyzed and confirmed even in a noisy quantum channel. 
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" ' , Suppose Alice wants to send a secret message to two distant parties. Bob and Charlie. One of them, 

(^ , Bob or Charlie, is not entirely trusted by Alice, and she knows that if the two guys coexist, the honest 

jii. , one will keep the dishonest one from doing any damages. Instead of giving the total secret messages 

^5 , to any one of them, it may be desirable for Alice to split the secret messages into two encrypted parts 

Mh, and send each one a part so that no one alone is sufficient to obtain the whole original information but 

"^ , they collaborate. To gain this end classical cryptography can use a technique called as secret sharing 

2 . [I72], where secret messages are distributed among N users in such a way that only by combining 
^^, their pieces of information can the N users recover the secret messages. Recently this concept has 
^ , been generalized to quantum scenario [3]. The quantum secret sharing (QSS) is likely to play a 

k^ , key role in protecting secret quantum information, e.g., in secure operations of distributed quantum 

3 , computation, sharing difficult-to-construct ancilla states and joint sharing of quantum money [6], and 

so on. Hence, after the pioneering QSS work proposed by using three-particle and four-particle GHZ 
states [3], this kind of works on QSS attracted a great deal of attentions in both theoretical and 
experimental aspects [4-13,24-26], and various methods were proposed to realize QSS. Entanglement 
swapping [14,15,27] is a method that enables one to entangle two quantum systems that do not have 
direct interaction with one another. Based on entanglement swapping, a number of applications 
in quantum information [16] have been found such as constructing a quantum telephone exchange, 
speeding up the distribution of entanglement, correcting errors in Bell states, preparing entangled 
states of a higher number of particles, and secret sharing of classical information. Entanglement 
swapping is also used in QSS protocols [7,12], however, in those multi-party QSS protocols [3,4,11,12] 
the identification of multi-qubit GHZ states are required and should be achieved. In fact, according 
to the present-day technologies an identification of a Bell state is much easier than an identification of 



a GHZ state. In this paper, we propose a multi-party quantum secret sharing (QSS) protocol based 
completely on the entanglement swapping and identification of Bell states. 

Before giving our protocol, let us briefly introduce the local unitary operations which can impose 
secret messages on Bell states and the entanglement swapping of Bell states. Define the four Bell 
states as 
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where |+) = -^dO) + |1)) and |-) - -i^dO) - |1)). Let u, = |0)(0| + |1)(1|, U2 - |0)(0| - |1)(1|, u^ - 
|1)(0| + |0)(1|, U4 = |0)(1| — |1)(0| be four local unitary operators acting on one qubit of the qubit pair 
in a Befl state, then one can see that ui|*") = |*"),?i2|*") = |*+),U3|*") = |$+),U4|*") = |(f>"). 
Assume that each of the above four unitary operations corresponds two classical bits respectively, 
i.e., uo to '00', ui to '01', U2 to '10' and u^ to '11', then the encodings of the secret messages can be 
imposed on the Bell states by using the local unitary operations. Since the following equations hold, 

Kl*:.)) ® I* J - I* J ® I* J - ^(l*ac>l*M> + l*a+ >l*iz> - l*+ )l*iz> - l*ac>l*,-,», (5) 

Kl*:,)) « \Kd) - l*+.) ® I* J - ^(l*a+ >I*m) - l*ac>l*iz) - l*+ >l*,-,> + l*ac>l*^,», (6) 

MKb)) ® l^c^d) = \Kb) ® l*;d> = ^(l*ac>l*iz> - l*^c)l*6d) - \'^ac)\Kd) + l*^c>l*."d», (7) 

Kl* J) ® \Kd) - l^o^fc) ® 1*;^) - ^(l*^c>l*^d> + l*ac>l*M> - \'^ic)\Kd) - l*ac)l*6d», («) 

obviously, one can see that there is an explicit correspondence between a known initial state of two 
qubit pairs (secret encoding has been imposed on one pair via a local unitary operation) and its 
Bell-state measurement outcomes after the quantum entanglement swapping. 

For convenience, let us first describe a three-party QSS protocol. Suppose there are three parties, 
say, Alice, Bob and Charlie. The sender Alice wants to distribute secret messages between two parties, 
Bob and Charlie. To reach this goal, they do as follows. 

(SI) Each party prepares two qubits in the same Bell state, say, |^~), that is, Alice (Bob, Charlie) 
prepares |vE'j~2) (l^iw)' l^se)) i^^-' figl^)- Then each party stores one qubit in its own site and sends 
another to the specific partner, e.g., Alice (Bob, Charlie) sends the qubit 2 (4, 6) to Bob (Charlie, 
Alice) (cf., figlb). They should publicly confirm whether the success of the qubit distributions has 
been achieved. If succeed, Alice can decide to select which one out of the following two possible 
choices. With probability c Alice selects the first choice which we call as detecting mode hereafter. 
The aim of this choice is to check the security of qubit transmission quantum channels. If this mode is 
selected, the procedure continues to (S2). In contrast, Alice can decide to select the second choice with 
probability r = 1 — c. The aim of the second choice is to impose the secret message and implement 
the QSS. We call this choice as message mode. If this mode is selected, the procedure goes to (S3). 
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FIG. 1: The detecting mode (a-b-c) and the message mode (a-b-d-e) of the present quantum secret sharing 
protocol. The hollow circle stands for a qubit. The line between two qubits represents their entanglement. 
The solid circle in (d) means that a unitary operation has been performed on the qubit. See text for detail. 



(52) Alice chooses randomly one of the two sets of measurement basis (MB), say, Xz= {|1), |0)} 
and Xx= {|+), |~)} to measure qubit 1. Then Ahce tells Bob which MB she has chosen and her 
measurement outcome. Bob uses the same MB as Alice to measure qubit 2 and compares his outcome 
with Alice's (cf., figlc). If no eavesdropping exits, their outcomes should be completely opposite, i.e., 
if Alice gets |0> (|1)), then Bob gets |1> (|0)) and if Alice gets |+) (|-)), then Bob gets |-> (|+)). This 
method is sufficient to check whether the Alice-Bob channel is secure. In fact, in the present protocol 
there are three qubit transmission quantum channels, namely, the Alice-Bob, the Bob-Charlie and 
the Charlie-Alice quantum channels. Above we only consider the security of the Alice-Bob channel. 
Due to symmetry, security considerations of other channels are same. For simplicity, here we do not 
depict others anymore. Only when they ascertain that there is no Eve in each channel, they turn to 
(SI). Otherwise, the QSS is aborted. 

(53) Firstly, Alice performs a local unitary operation randomly on one of her two qubits 1 and 
6 (cf., figld). Then she performs a Bell-state measurement on the qubits 1 and 6 and announces 
publicly her measurement outcome. After this, Bob and Charlie perform Bell-state measurements on 
their own qubits respectively and record the measurement outcomes. As a matter of fact, after Alice's 
Bell-state measurement, the qubits 2 and 5 should project to one of the four Bell states (cf., figle). If 
Bob and Charlie collaborate, according to their Bell-state measurement outcomes and Alice's public 
announcement of the Bell-state measurement on the qubits 1 and 6, they can deduce the exact local 
unitary operation which Alice performed on one of her qubits in terms of eqs.(5-8) in a recursion way. 
For an example, if Bob's and Charlie's outcomes are respectively I'l'^s) and |'I'45), since the state Bob 
prepared in his initial qubits 3 and 4 is 1^34), then from Eq. (7) they can know that the qubits 2 



and 5 has projected to |$25) after Alice's Bell-state measurement on qubits 1 and 6. Since both the 
initial states of the qubit pair (1, 2) and the initial states of the qubit pair (5,6) are |^^), respectively, 
and Bob and Charlie have known Alice's Bell-state measurement outcome on the qubits 1 and 6 (say, 
l^l'j'g)) and they have already deduced out the state I^^J^) of qubits 2 and 5, then from Eq. (8) they 
can know that the local unitary operation performed by Alice is U4, that is, the secret messages Alice 
distributed is the two classical bits '11'. 

So far we have presented a three-party QSS protocol completely based on the quantum entanglement 
swapping and identification of Bell states. Now let us analyze the security of the protocol. Since for 
each qubit pair only one qubit is transmitted via a quantum channel. Eve can not distinguish this 
Bell state of the pair with any local operations on this qubit. In order to acquire Alice's transmitted 
information, the efficient eavesdropping is to capture the travel qubits and replace them with their 
own qubits prepared previously. But this eavesdropping can be detected in the detecting mode by 
using randomly chosen MB and comparing the measurement outcomes. Even if in a serious case that 
an insider, say Charlie (Charlie*), cooperate with an outside eavesdropper Eve, the eavesdropping 
can also be detected in the detecting mode. Our protocol is based on EPR pairs, so the proof of 
the security is same in essence as those in Ref. [17-21]. Hence the present protocol is secure against 
eavesdropping. 

Above we have presented a three-party QSS protocol based on entanglement swapping. In fact, it is 
easily generalized to a multiparty case. Suppose there are N parties. At first, each party prepares two 
qubits in the Bell state |^^). Then each of them sends one qubit to the specific partner and retains 
another in its own site, that is, the nth party prepares a qubit pair in |^^), then he (or she) sends 
one qubit to the (n + l)th party and stores one in own site (the A'^th party sends one qubit to the 
first party). After this procedure is successfully finished, they also have two choices. One choice is to 
detect eavesdropping. Its deatiled procedure is very similar to and the same in essence as that in the 
three-party QSS protocol. Hence the security of the generalized version can be confirmed. The other 
is to distribute the secret messages among the other parties. The sender (say, Alice, whose n order 
is assumed to be the smallest or the largest one) performs a local unitary operation on one of her 
two qubits. Then Alice measures this two qubits in the Bell basis and announces the measurement 
outcome. After this, according to the order of n is always increased (or decreased), each of the 
other parties performs in turn the Bell-state measurement on the two qubits in its own site. If they 
collaborate, they can successfully extract Alice's secret messages in a recursive way. Incidentally, in 
the generalized protocol, the order of measurement is very important. Once such an order is destroyed, 
then the secret message can not be correctly extracted by the other parties though they collaborate. 

It should be pointed out that the above protocol seems to be only designed for ideal quantum 
channels. In the above protocol the reliable sharing of an entangled qubit pair between two parties is 
very important and necessary. It is known that when a qubit of an entangled pair travels in a noisy 
quantum channel, the initial entanglement might be lost. Hence the security problem of the above 
protocol in a noisy channel seems to arise. Fortunately, it has been proven that over any long distance 
two party can reliably share an entangled pair in terms of the quantum repeater technique containing 
the entanglement purification and teleportation[28-32]. Once two parties have shared an entangled 



qubit pair, then in the detecting mode any eavesdropping can be detected by using the method of 
two MBs. Hence, even in a noisy channel the present protocol works securely also. 

Our protocol owns two distinct advantages over those protocols using directly multi-particle GHZ 
states. First, as mentioned in [12], in the present protocol the parties can apply the entanglement 
purification protocol to reliably share a qubit pair in a Bell state[22,23]. However, for those protocol 
using GHZ states, when the number of all the parties is large, how to prepare a multi-qubit GHZ state 
and how to reliably share the GHZ states among multiparties are worthy to be studied further so far 
[33]. Secondly, in the present protocol only Bell states are used. The advantage of such limitation is 
dominant. For instance, as for as a ten-party protocol is concerned, if multi-particle GHZ states are 
used, one should prepare 511 different multi-particle GHZ states in advance [See Ref.l2] and perform a 
more difficult multi-particle GHZ state measurement. However, in the present protocol, we only need 
ten Bell states as well as the Bell state identification. Incidentally, we realize that the experimental 
realization of full Bell measurement still represents an unsolved problem, which affects the advantage 
over some GHZ-based protocols. 

To summarize, we have presented a multi-party QSS protocol based on entanglement swapping of 
Bell states. The security of the protocol has been confirmed, even in a noisy quantum channel. The 
advantages of the present protocol are revealed. 
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